skills/aeondave/malskill/stegseek/Gen Agent Trust Hub

stegseek

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing the stegseek and steghide shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted media files (JPEG, BMP, WAV, AU) that may contain hidden instructions intended to influence the agent. * Ingestion points: Processes external artifact files provided by the user or found in the environment (SKILL.md). * Boundary markers: The instructions lack boundary markers or warnings to the agent to ignore instructions embedded in the artifacts. * Capability inventory: The skill utilizes shell command execution via stegseek and steghide (SKILL.md). * Sanitization: No sanitization or validation mechanisms for the media artifacts are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — stegseek